MAC Flooding
MAC flooding attempts to overflow a switch’s MAC address table so forwarding behavior becomes less selective.
Mechanism
When a switch cannot associate destinations reliably, it may flood frames more broadly within the relevant segment.
Indicators to watch
Rapid growth in learned MAC addresses, table exhaustion alerts, unusual source-MAC churn, and increased unknown-unicast traffic.
Concept diagram
Defensive controls
Enable port security, limit learned MAC addresses, segment networks, use storm controls, and monitor switch telemetry.
Recommended security control
Switch port-security monitoring
Use a virtual switch or isolated lab.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.